October 30, 2023

Attendees: 

 

  •  

Agenda Item

Background Docs & Links

Owner

Notes / Actions / Next Steps

Newcomer introductions

Five minutes to learn about people who are new to the group

@Lucas Gonze 

Welcome! And introduce yourself to the audience, please.

  • Proposal:
    Every attendde writes a two line intro in the meeting chat to intro themselves

v 1.9

 

@Yogesh Pandey for 1.9

 

 

Update on 1.9 features:

Oct-30

  • DevOps Issue : #15332 (liblsan and gcc). Proposed approaches

  • Features & Issues

New ASN proposal (#15317). Framework chosen is 

  

OpenSSF Best Practices Badge

https://github.com/magma/security/issues/154

(was https://github.com/magma/magma/issues/15212)

Lucas Gonze 

OCT 30 Update:

  • #154 is closed

 

Oct- 9 Updates

SAST triage

Proposal: triage all SAST issues

https://github.com/magma/magma/issues/15329

@Lucas Gonze 

Introduce project

Call to open voting was made and accepted. Call for votes in email to be issued.

Bug Bounty Program

@Lucas Gonzeis out Oct 26, 2023
He has requested a vote to be initiated at this meeting for the Bug Bounty Proposal 

-- Som Sikdar

  • Waiting on bounty items for v1.9 from @Yogesh Pandey )

Sept 25 Updates

Progress made on documentation -

Task definition was too loose to come up with a bounty 

Lucas - If bounty should be for community members already cleared?

Jordan- bounty is to bring in new members, there's already a mechanism for members already contributing

10/16 update: https://github.com/magma/magma/issues/15325 ready for a vote.

@Sandra Jackson (Deactivated) to follow up with Ben next steps to publish the bug bounty. Check to see if @Ben Sternthal has time for a zoom to explain.

 

Proposal to move Magma to LF Connectivity

Request for comments on a proposal to move Magma to Linux Foundation for connectivity to facilitate more symbiotic community growth:

  1. Shared folder with proposal and FAQ (read-only)

  2. Doc to collect questions from community (read/write)

  3. magma-lfc - magma - Slack

Som Sikdar 

OCT 30, 2023 -
- Proposed LF Connectivity Governance Docs for 2024 

In the onboarding Folder - LFC-Magma-Onboarding - Google Drive

 


OCT 23, 2023 - 
LFC tab will attend the Townhall on Oct 26

  • Checking with LF to see if a blog entry is appropriate 

 

OCT  9 - No new update

Oct 2 update: (Som)

  • Proposal has been provided by LF legal

  • LF Connectivity is reviewing on Oct 11

  • Target is to complete legal requirements completed for the Oct 26 townhall to be a LFC event

  • Adding agenda item for LFC 

 

 

Outreach Report

  • Starter kit

  • Town Hall

Som Sikdar 

Action items:
OCT 30


  • Unfortunately, the town hall needs to be rescheduled. As reported from LF, this is a very unusal error and it happened due to issues with how the zoom meeting was scheduled on their event platform (Bevy).

  • More updates expected when @Sandra Jackson (Deactivated) is back

  • The proposed reschedule date is Nov 9th 7AM Pacific. Need TSC approval for this date. 

OCT 23

 

(Oct 9 Updates):

  1. ongoing items

    1. LF Connectivity advisory board confirmed for OCT 26th

    2. Invitation has gone out

    3. (Som) at
      Magma Townhall Planner - October , 2023 - Google Docs


    4. (Som) Create a one-pager for items that will be a 'Magma Community Edition' starter kit
      -- MagmaCommunityEdition - Starter Kit Overview - Google Docs


2. Feedback from @Lucas Gonze - we need to start thinking about a working group, hopefully with new participants - who can offer ideas on the starter kit documentation. Existing contributors are maxed out and it will be useful to get feedback fom actual deployers.

K8s 

General discussion on interest in eBPF project (migration from OVS)

@Pravin Shelar 
@Jordan Vrtanoski 
@Som Sikdar 

OCT 30

 

  • eBPF presentation from @Pravin Shelar - Magma ebpf2 - Google Slides

  • k8s (@Jordan Vrtanoski ) - performance improvement has been observed. More details coming

 

OCT 9 

(Bruno) - Work in progress for a proposal.

Secret scanning

Review latest output

https://github.com/magma/magma/security/secret-scanning

@Lucas Gonze 

@Lucas Gonze 

@Sandra Jackson (Deactivated) follow up with @Ben Sternthal  regarding management of Magma slack channel.

Orc8r API cert

requiring the certificate in the orc8r API server

https://github.com/magma/magma/issues/15328

@Lucas Gonze 

Technical discussion

  • (@Jordan Vrtanoski ) This appears to be a vulnerability and can compromise via access to the AGW


  • (@Lucas Gonze ) This potentially can be a high-severity item. 

    Shall be discussed in detail in a closed (off-recording) session
    Lucas proposes activating a workstream to look into this.


Reminder to Review Latest Q&A

 

OCT 30

Review new GitHub offline

 

Recording: